Digital Sovereignty at Any Cost? – What Happens When Data Protection Concerns Meet Reality (Part 2)
This blog post examines questions surrounding digital sovereignty. More specifically: is the call for digital sovereignty understandable in the case of the encrypted Senate administration? And where is digital sovereignty currently failing in the EU?
Since the content of this blog post is based on the cyberattack against two Berlin Senate administrations, I recommend reading the first part of this series.
Chapter 1: What Is Digital Sovereignty?
Digital sovereignty is not a clearly defined term. Generally speaking, however, it refers to the ability of individuals, public authorities and states to control IT infrastructure, data and processes securely and independently. This applies particularly to critical infrastructure and sensitive information.
Chapter 2: The Call for Digital Sovereignty – Fear of CrowdStrike Espionage
Following the cyberattack, the Berlin Senate commissioned the US company CrowdStrike to investigate the incident. CrowdStrike provides international support services to companies that are acutely affected by—or suspect that they may be affected by—cyberattacks. However, its deployment was delayed because there was opposition in the Lichtenberg district.
Lichtenberg rejected cooperation with the incident response provider, with the core of its reasoning being understandable: there were concerns about data protection. The Falcon Agent tool reportedly had virtually unlimited data access privileges and also enabled the monitoring of work devices. It was furthermore impossible to ensure that the software would be removed completely. In addition, its use could result in “partly severe disruptions to the operational functionality of specialist applications, services and programs, and pose a significant risk to the district administration’s ability to operate.”
The district also stated that no evidence of a compromise had been discovered up to that point. It is not publicly known whether or to what extent this could be verified or ruled out through an independent forensic investigation by the district. Florian Hauer (CDU), Berlin’s State Secretary for Digitalization, ultimately described the use of CrowdStrike as “without alternative.” Why he appears to be unaware of the BSI’s list of qualified APT response providers remains unanswered.
The district eventually agreed to the deployment. However, it would only permit the use of the software if the Senate assumed “full responsibility” and covered all associated costs. In return, the Senate referred to contractual assurances from CrowdStrike. The data would be stored exclusively within the EU and would be deleted in full once the contract ended.
All’s well that ends well—or is it?
Chapter 3: Hypothetical Concerns vs. a Real Security Incident
As logical as the district’s initial argument regarding digital sovereignty may appear, it seems rather incomplete upon closer examination. There are two reasons for this.
a. Risk Assessment: Hypothetical Scenarios and the Real Security Incident
The prompt investigation of security incidents is important for a wide range of reasons. It is therefore particularly serious when the service provider is unable to begin its investigation in a timely manner.
Logs, memory contents, network traffic and digital artifacts—all of this information has a limited lifespan, yet it may become relevant, particularly when it comes to reliably detecting persistence mechanisms. Regulatory requirements provide another reason. NIS2, in particular, requires a final report or a detailed progress report no later than one month after the incident. Forensic investigations, however, are time-consuming. A substantial delay can therefore create both practical and regulatory risks.
Moreover, there is currently no publicly known case in which CrowdStrike has forwarded information from incidents involving public authorities in other countries to the US government. In this risk assessment, hypothetical scenarios are therefore being weighed against actual damage. Data has already been exfiltrated and is theoretically accessible to anyone.
Of course, one could argue that CrowdStrike might gain access to significantly more critical information. In that case, however, this logic would have to be applied consistently as follows.
b. Trustworthy vs. Untrustworthy Vendors
To quote the Chaos Computer Club, it is important to consider “who we allow to process our sensitive data, and where.” But CrowdStrike is also “a respected and established provider of attack-detection software.”
Admittedly, the company is based in the United States. Under the CLOUD Act, US authorities may potentially gain access to all data processed by such a company. On the other hand, one would also have to apply this logic consistently to the entire range of tools and software used.
Anyone who assumes that an incident response provider might install backdoors in their own network would, in principle, also have to suspect the same of well-known operating system manufacturers.
Chapter 4: Digital Sovereignty—Yes, but Done Properly
So, is it wrong to call for digital sovereignty? Of course not. On the contrary, it is extremely important. But it is essential to ask the right questions.
a. Early Assessment of European Alternatives
In my view, the question of digital sovereignty is often framed incorrectly. The question should not be: Why did the Senate choose a US company in particular?
Rather, the question should be: Were European incident response providers sufficiently considered during the procurement process, or why were they excluded?
Proactive planning—determining how to respond to incidents, which providers should be considered and which can be categorically ruled out—is what demonstrates genuine digital resilience in the first place.
b. Data Storage Is Not the Same as Data Processing
Another misconception is the assumption that storing data within the EU is sufficient to achieve digital sovereignty.
In practice, many providers and service companies advertise that data is stored within the EU. However, it is also worth checking the small print to determine whether the data is actually processed there as well.
After all, it would be little more than a digital fig leaf if my information were stored on EU servers but still transferred to US servers for processing—for example, by AI systems.
It is not publicly known whether CrowdStrike contractually guaranteed not only that the data would be stored within the EU, but also that it would be processed there.
c. The Risks of Digital Sovereignty at Any Cost
In the case of incident response providers, the following applies: technological alternatives within the EU theoretically existed. The question is how we should proceed in areas where this is not the case in practice.
The current draft of the Cloud and AI Development Act (CADA) is a prime example. Under the draft, the EU is supposed to achieve digital independence in cloud computing and artificial intelligence over the next seven years. To this end, systems are to be divided into four levels:
Level 1: Data must be physically located within the EU.
Level 2: Independence from the laws of third countries and transparent software supply chains.
Level 3: EU ownership and control.
Level 4: Complete transparency of the software supply chain and no possibility of influence by third countries.
According to the EU, only one percent of digital services would actually meet the requirements of Level 4. Once again, however, this illustrates how regulation and reality can diverge.
The fact is that, technologically, we are lagging behind when it comes to comparable alternatives for AI and cloud products—according to some estimates, by as much as a decade in certain specialized applications. Trying to make up for the shortcomings of past decades within just seven years therefore seems unrealistic.
Chapter 5: Conclusion
Digital dependence on third countries is a real threat. Building digital sovereignty is one of the most effective means at our disposal to counter it. One may debate whether the use of CrowdStrike in this particular case was genuinely “without alternative,” but we often fail to have this discussion proactively enough. Claudia Plattner appears to take a similar view: in a recent statement, she generally described digital sovereignty as achievable, while also pointing out that European alternatives are sometimes simply lacking.
The question should therefore not be whether we are allowed to rely on companies and expertise from third countries. Instead, we should ask:
Where do comparable European alternatives exist, and are we giving them sufficient consideration?
Are offerings from vendors in third countries that advertise digital independence genuinely digitally sovereign?
And in cases where no such offerings currently exist: can and do we realistically want to develop them within the next few years? If so, how?
Who is driving their development in these cases, and what will we do—or how will we respond—if this potential cannot be realized?